CVE-2017-15101
published 2018-07-27CVE-2017-15101: A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.7th percentile
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | liblouis | — | — |
| liblouis | liblouis | < 2.5.4 | 2.5.4 |
| liblouis | liblouis | — | — |
| liblouis | liblouis | >= 0 < 2.5.3-2ubuntu1.2 | 2.5.3-2ubuntu1.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxf5-6w8g-jf87: A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2
ghsa_unreviewed·2022-05-13
CVE-2017-15101 [CRITICAL] CWE-119 GHSA-hxf5-6w8g-jf87: A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
OSV
CVE-2017-15101: A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2
osv·2018-07-27·CVSS 9.8
CVE-2017-15101 [CRITICAL] CVE-2017-15101: A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
Red Hat
liblouis: incomplete fix for CVE-2014-8184
vendor_redhat·2017-11-02·CVSS 7.8
CVE-2017-15101 [HIGH] CWE-121 liblouis: incomplete fix for CVE-2014-8184
liblouis: incomplete fix for CVE-2014-8184
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
A missing fix for one stack-based buffer overflow in findTable() for CVE-2014-8184 was discovered. An attacker could cause denial of service or potentially allow arbitrary code execution.
Debian
CVE-2017-15101: liblouis - A missing patch for a stack-based buffer overflow in findTable() was found in Re...
vendor_debian·2017·CVSS 7.8
CVE-2017-15101 [HIGH] CVE-2017-15101: liblouis - A missing patch for a stack-based buffer overflow in findTable() was found in Re...
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15101 liblouis: incomplete fix for CVE-2014-8184
bugzilla·2017-11-08·CVSS 7.8
CVE-2017-15101 [HIGH] CVE-2017-15101 liblouis: incomplete fix for CVE-2014-8184
CVE-2017-15101 liblouis: incomplete fix for CVE-2014-8184
Incomplete fix of CVE-2014-8184: one possible stack-based buffer overflow missed in CVE-2014-8184 fix.
Discussion:
Acknowledgments:
Name: Samuel Thibault
---
Proposed patch by Samuel Thibault: https://github.com/liblouis/liblouis/files/1439794/CVE-2014-8184-fix.txt
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3384 https://access.redhat.com/errata/RHSA-2017:3384
Bugzilla
CVE-2014-8184 liblouis: stack-based buffer overflow in findTable()
bugzilla·2017-09-18·CVSS 7.8
CVE-2014-8184 [HIGH] CVE-2014-8184 liblouis: stack-based buffer overflow in findTable()
CVE-2014-8184 liblouis: stack-based buffer overflow in findTable()
A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
Discussion:
Acknowledgments:
Name: Raphael Sanchez Prudencio (Red Hat)
---
Hi
Can you share details on this issue? Is upstream aware of the details?
I found only https://github.com/liblouis/liblouis/issues/425 asking Upstream on it.
Regards,
Salvatore
---
(In reply to Salvatore Bonaccorso from comment #5)
> Hi
>
> Can you share details on this issue? Is upstream aware of the details?
>
> I found only https://github.com/liblouis/liblouis/issues/425 asking Upstream
> on it.
>
> Regards
2018-07-27
Published